docker-compose.proxy.yml runs the container on a shared external 'proxy'
network with no published ports, for hosting behind an existing edge
proxy (Caddy/Traefik/etc.) that routes <sub>.domain -> the-director:80.
This is how it's deployed at apps.timevans.uk.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>